SV-222432r508029_rule
V-222432
SRG-APP-000065
APSC-DV-000530
CAT I
10
Configure the application to enforce an account lock after 3 failed logon attempts occurring within a 15-minute window.
All testing must be performed within a 15-minute window.
Log on to the application with a test user account.
Intentionally enter an incorrect user password or pin.
Repeat 2 times within 15 minutes for a total of three failed attempts.
Notification of a locked account may or may not be provided.
Using the correct user password or pin, attempt to logon a 4th time.
If the logon is successful upon the 4th attempt the account was not locked after the third failed attempt and this is a finding.
V-222432
False
APSC-DV-000530
All testing must be performed within a 15-minute window.
Log on to the application with a test user account.
Intentionally enter an incorrect user password or pin.
Repeat 2 times within 15 minutes for a total of three failed attempts.
Notification of a locked account may or may not be provided.
Using the correct user password or pin, attempt to logon a 4th time.
If the logon is successful upon the 4th attempt the account was not locked after the third failed attempt and this is a finding.
M
4093